Laravel's AI SDK just dropped. So did six zero-days. Here's what matters.
Two things happened this week that deserve your attention, and they pull in opposite directions. One is about building faster. The other is about not getting owned.
Let's start with the fun one.
Laravel now has a first-party AI SDK
On February 5th, the Laravel team officially released the Laravel AI SDK. It's in beta (v0.1.2), but it's real, it's documented, and it's already generating a lot of buzz. The SDK gives you a unified API for working with multiple AI providers, including OpenAI, Anthropic, Google Gemini, Groq, and xAI, all through one consistent interface. Install it with composer require laravel/ai and you're off.
The interesting part isn't just the provider abstraction. It's the Agent pattern. You run php artisan make:agent and get a dedicated class where you define instructions, tools, conversation context, and output schemas. Agents are testable, composable, and follow the same conventions Laravel developers already know. There's also agent middleware for intercepting and modifying prompts, conversation persistence, streaming responses, and built-in failover between providers.
Vector search and embeddings require PostgreSQL with pgvector, which makes sense given that Laravel 12 added native vector search support. Standard text generation, images, and audio work with any database.
This is a big deal for the PHP ecosystem. For years, building AI features in Laravel meant stitching together community packages, hand-rolling Guzzle requests, and maintaining your own abstraction layer. We've done exactly that for client projects, and it's tedious work that every team ends up solving slightly differently. A first-party SDK with sensible defaults changes that equation.
From our PHP and Docker work with enterprise clients, I can tell you the pattern is familiar: Laravel does this well. They wait until the community has figured out the rough shape of a problem, then ship an official solution that's cleaner and better integrated than anything third-party. They did it with Cashier for payments, Socialite for OAuth, Scout for search. Now they're doing it for AI.
The MCP (Model Context Protocol) library shipped alongside it, letting you expose your app's functionality to AI clients like ChatGPT and Claude. Combined with Laravel Boost for AI-assisted development, there's now a full AI section in the Laravel docs covering three packages that work together.
So, should you adopt it today?
For new projects: yes, absolutely explore it. The API is clean and the docs are solid. For existing production apps, I'd take a more cautious approach. Introduce it alongside your current setup for a specific feature rather than ripping out what works. It's v0.1, and the API will probably shift. When we build cloud-native apps for enterprise clients, we rarely adopt dot-zero releases in production, and that advice holds here too.
One thing to watch: the SDK uses Prism under the hood. If you're already using Prism directly, you'll want to understand what the SDK adds before migrating, since it's a wrapper with Laravel-specific extras rather than a replacement.
Six zero-days in this week's Patch Tuesday
Now the less fun part.
Microsoft's February 2026 Patch Tuesday dropped on the 10th with fixes for around 54 CVEs. Six of them are zero-days that were already being actively exploited before patches were available. That's a lot.
Here's what's getting exploited right now:
- CVE-2026-21510: a Windows Shell bypass (CVSS 8.8) where a single click on a malicious link bypasses SmartScreen protections entirely. No warning dialogs, no consent prompts. It affects all supported Windows versions.
- CVE-2026-21513: an MSHTML framework bypass (CVSS 8.8) triggered by opening a malicious HTML or .lnk file. Yes, Internet Explorer components are still causing problems in 2026.
- CVE-2026-21514: a Microsoft Word bypass (CVSS 7.8) where opening a crafted document lets attackers bypass OLE mitigations.
- CVE-2026-21519: a Desktop Window Manager privilege escalation (CVSS 7.8) that gives attackers SYSTEM-level access. This is the second month in a row for a DWM exploit, which suggests last month's patch didn't fully resolve it.
- CVE-2026-21533: a Remote Desktop Services privilege escalation to SYSTEM. Don't let "Remote" fool you, it's a local bug, but RDS boxes are high-value targets for lateral movement.
- CVE-2026-21525: a denial-of-service in Windows Remote Access Connection Manager, which handles VPN connections.
Three of these (21510, 21513, 21514) were discovered jointly by Google's Threat Intelligence Group and Microsoft's own teams, which hints they may have been used in the same campaign. Nation-state or commercial spyware is the likely context.
On top of the zero-days, there's CVE-2026-20841, an RCE in Windows Notepad (CVSS 8.8) triggered by opening a crafted Markdown file and clicking a link. And CVE-2026-21531 in the Azure SDK scores a 9.8, potentially allowing arbitrary code execution on any machine talking to Azure services.
There's also a Microsoft Outlook spoofing vulnerability (CVE-2026-21511, CVSS 7.5) where the preview pane is an attack vector, meaning you don't even need to open the email.
And here's a detail that should worry development teams specifically: this Patch Tuesday includes RCE fixes for GitHub Copilot and multiple IDEs including VS Code, Visual Studio, and JetBrains products. Your development environment is an attack surface.
What you should actually do
During our penetration testing engagements, we regularly see organizations that are weeks or months behind on patching. Six actively exploited zero-days in a single release isn't routine. CISA has added these to the Known Exploited Vulnerabilities catalog with a patch deadline of March 3rd, but honestly, if you have Windows machines in your environment, this should be happening now, not in three weeks.
Specific actions:
- Patch Windows immediately. Prioritize the six zero-days, then the Azure SDK (9.8 CVSS), then everything else.
- Update your IDEs. The Copilot and IDE RCEs mean your developers' machines are targets. When configuring Cloudflare or Akamai for DDoS protection, we always stress that security isn't just about production servers. Dev machines with access to repos, cloud credentials, and internal tools are arguably more valuable targets.
- Check your Outlook configuration. CVE-2026-21511 can trigger from the preview pane. If your org uses Outlook, this is a "read your email and get owned" scenario.
- If you're running the Laravel AI SDK, review what data flows through your agents. AI integrations tend to get broad permissions quickly because it's easier than scoping them properly. In our native iOS and Android projects, we've seen the same pattern with on-device ML models: teams ship with overly permissive data access because the feature was built under deadline pressure. Apply the same discipline to server-side AI agents. Scope their tools, audit their access, and don't give an agent access to anything it doesn't need.
- Check your Laravel version while you're at it. Laravel 12 gets bug fixes until August 2026 and security fixes until February 2027, so you have time, but if you're still on Laravel 10 or 11, start planning your upgrade path.
The RCE-in-Notepad story (CVE-2026-20841) is genuinely wild. A Markdown file. In Notepad. Leading to code execution. We've seen this pattern in healthcare and IoT apps we've built, where seemingly harmless file-handling operations become attack vectors because nobody expected that code path to matter. The same thinking applies here: if Notepad can be an RCE vector, reassess your assumptions about what's "safe" in your own applications.
The bigger picture
The Laravel AI SDK and six zero-days in the same week tell the same story from different angles: the surface area of modern software keeps expanding. AI integrations add new provider dependencies, new data flows, new prompt injection risks. And the foundation we build on, Windows, Office, our own dev tools, keeps revealing new holes.
Neither of these things is a reason to panic. The Laravel SDK is well-designed and follows patterns the community already understands. The Patch Tuesday fixes are available and should be applied. But both are reminders that building software in 2026 means holding two things in your head at the same time: how to move fast and how to not get caught with your defenses down.
If your team is dealing with the balancing act of shipping AI features while keeping your infrastructure locked down, or if six zero-days in one month sounds like more than your internal team can handle, let's talk. That's the kind of problem we help with every day, across web applications, mobile apps, and security.